CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++
Sdk For ยท 2026-09-09
Actions
Technical Details
| Affected Versions | <= 1.11.861 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-19642, CVE-2026-19643 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the AWS SDK for C++ to version 1.11.862 to address critical memory-safety issues in the Base64 decoder and ensure the application's process performing the decode remains stable and secure.
For Platform Teams
Adopt the updated AWS SDK for C++ version 1.11.862 to integrate the new Base64 implementation from the AWS Common Runtime, enhancing the platform's security and stability.
For Executives
Implement the upgrade to AWS SDK for C++ version 1.11.862 to mitigate security vulnerabilities (CVE-2026-19642 and CVE-2026-19643) and ensure application stability and security.
Source
Related Sdk For Updates
- Introducing a standalone SigV4 signer for the AWS SDK for .NET (2026-08-31)
- CVE-2026-6550 - Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python (2026-08-20)
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ (2026-08-20)
- CVE-2026-19642 & CVE-2026-19643 - Memory-safety issues in the Base64 decoder in the AWS SDK for C++ (2026-08-12)